Critical severity9.8NVD Advisory· Published Jul 31, 2025· Updated Jun 16, 2026
CVE-2013-10040
CVE-2013-10040
Description
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:*range: <=2.6
- (no CPE)range: <=2.6
- (no CPE)range: *
Patches
Vulnerability mechanics
References
4- packetstorm.news/files/id/123480nvdExploitThird Party Advisory
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/clipbucket_upload_exec.rbnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/clipbucket-arbitrary-file-upload-rcenvdThird Party Advisory
- clipbucket.comnvdProduct
News mentions
0No linked articles in our index yet.